Known vulnerabilities in the Funnelforms Free plugin
16 security advisories have been published for the Funnelforms Free plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Funnelforms Free - PHP Object Injection (CVE-2024-10587) HIGH
- Funnelforms Free - Broken Access Control (CVE-2024-5857) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2024-7447) MEDIUM
- Funnelforms Free - Remote Code Execution (CVE-2024-6312) MEDIUM
- Funnelforms Free - Remote Code Execution (CVE-2024-6311) HIGH
- Funnelforms Free - Cross-Site Request Forgery (CSRF) (CVE-2023-5990) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2023-5419) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2023-5417) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2023-5416) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2023-5415) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2023-5411) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2023-5386) MEDIUM
- Funnelforms Free - Cross-Site Request Forgery (CSRF) (CVE-2023-5382) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2023-5387) MEDIUM
- Funnelforms Free - Broken Access Control (CVE-2023-5385) MEDIUM
- Funnelforms Free - Cross-Site Request Forgery (CSRF) (CVE-2023-5383) MEDIUM